mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
9e225a279b33e4e6e1452e573a40a6a25aa2cb2f
19656
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
49ad6546d4 |
docs: add Deployment & Branching cross-link on Database overview (#48509)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Adds a cross-link from the Database overview's "Next steps" section to the Deployment & Branching guide, so readers who land on Database looking for Branching docs can find them without guessing at top-level nav. Closes DOCS-1263. ## What is the current behavior? - Linear item: [DOCS-1263](https://linear.app/supabase/issue/DOCS-1263/add-deployment-and-branching-cross-link-on-database-overview-next) - User feedback: someone looking for Branching docs expected them under Products → Database. The canonical docs live under Build → Deployment & Branching (`/guides/deployment`, with Branching at `/guides/deployment/branching`). That placement stays correct (it's a preview/deploy workflow, not a Database product guide) — the miss is that Database overview's "Next steps" grid has no link out to it. ## What is the new behavior? - Added a "Deployment & Branching" card to `databaseNextSteps` in `apps/docs/data/content-listings/database.data.ts`, linking to `/guides/deployment` (the Deployment & Branching hub, not a Branching-only link) - No nav changes, no URL redirects, no Features sidebar work ## Additional context - Worktree: `~/GitHub/supabase/supabase-worktrees/nrichers/docs-1263-add-deployment-branching-cross-link-on-database-overview` - Change is a single data-file addition (`databaseNextSteps` array), rendered on `/guides/database/overview` via `<ContentListings id="database-next-steps" />` - Verification: reviewed diff for correct schema shape (matches existing `ContentListingGroup` items, e.g. the existing cross-product `Backups` → `/guides/platform/backups` entry) ### Proof: Database overview "Next steps" now links out to Deployment & Branching **Verified:** docs preview deploy (pass) · both URLs return `200` · new card renders next to "Roles and permissions" and links to `/guides/deployment` ### Before & After | [Before (production)](https://supabase.com/docs/guides/database/overview) | [After (PR preview)](https://docs-git-nikrichers-docs-1263-add-deployment-br-fd2915-supabase.vercel.app/docs/guides/database/overview) | | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | |  |  | - **Before:** https://supabase.com/docs/guides/database/overview - **After:** https://docs-git-nikrichers-docs-1263-add-deployment-br-fd2915-supabase.vercel.app/docs/guides/database/overview ### Test plan - [x] Visit `/guides/database/overview` on the PR preview and confirm the "Next steps" grid shows a **Deployment & Branching** card - [x] Confirm the card links to `/guides/deployment` (not `/guides/deployment/branching`) - [x] Confirm no other Next steps cards, nav items, or redirects changed Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
d8491cc0cc |
Remove unvalidated pricing, improve direction to help users (#48534)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs fix/update ## What is the current behavior? Shows pricing information that is not accurate/approved yet ## What is the new behavior? helpful docs, which indicate pricing may be relevant and the future and already directs users to help management tools ## Additional context NA <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated Logs pricing and quota guidance to clarify that details may change before billing enforcement begins. * Replaced preliminary pricing tables and billing examples with notices that finalized information will be published later. * Expanded usage optimization guidance for log ingestion and querying, including filtering, time ranges, polling, and database logging recommendations. * Directed readers to per-SKU pages for the latest pricing, quotas, billing, and optimization information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
80866c6f22 | docs(self-hosted): add updating how-to (#48535) | ||
|
|
c8954e6054 |
docs(security): add GDPR, ISO 27001, and DDoS coverage to security guide (#48449)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This is a docs-only content update to the `/docs/guides/security` landing page and its neighboring guides. It adds a dedicated GDPR compliance guide, and surfaces ISO 27001 and DDoS protection coverage that Supabase already provides but wasn't listed anywhere in the docs security guide. Closes DOCS-354. ## What is the current behavior? - In `/docs/guides/security`, there is no mention of GDPR, ISO 27001 or DPA request potential, despite Supabase docs covering these partially in one place or another. - Confirmed by auditing `apps/docs/content/`: zero mentions of GDPR/data residency, zero DPA content or link to `/legal/dpa`, zero ISO 27001 mentions, and only incidental/wrong-audience mentions of DDoS protection (a pen-testing exclusion, a Storage CDN aside, a fail2ban troubleshooting article for banned users). - `regions.mdx` only frames region choice as a performance decision, with no data-residency/compliance angle. - This is a parallel docs-side counterpart to #48403 (marketing `/security` page content additions), which is adding the same GDPR/Data Residency/DPA/DDoS topics on `apps/www`. This PR does not modify `apps/www` — see that PR for the marketing-page changes. ## What is the new behavior? - New guide: `apps/docs/content/guides/security/gdpr-compliance.mdx` covering data residency (including the nuance that the "Europe" general region grouping includes non-EU jurisdictions UK and Switzerland) and the Data Processing Agreement (DPA), linked to `/legal/dpa`. - Added to the sidebar nav under Security → Compliance, alongside SOC 2 and HIPAA. - `apps/docs/content/guides/security.mdx`: added an ISO 27001 paragraph (dashboard certificate link, matching the existing SOC 2/HIPAA pattern) and a GDPR pointer paragraph to `## Compliance`; added a DDoS protection paragraph (Cloudflare CDN + fail2ban) to `## Platform configuration`. - `apps/docs/content/guides/platform/regions.mdx`: added a "Data residency" section clarifying that general region groupings may span non-matching jurisdictions, and specific regions should be used when strict jurisdictional residency is required. ## Additional context - Worktree: `~/GitHub/supabase/supabase-worktrees/nikrichers/docs-354-security-landing-page` - Note: Supabase's subprocessor list was considered for the GDPR guide but omitted — both candidate links (`/legal/customer-resources/subprocessor-list` and `/legal/privacy#subprocessors`) are not yet publishable/live. Follow up once Legal publishes that page. **Verification:** | Check | Result | | ------------------------------------ | ----------------------------------------------------------------------------------------------------- | | `pnpm lint:mdx` on changed/new files | Pass (0 errors, 0 warnings on touched files) | | `pnpm build:guides-markdown` | Fails on `master` too (unrelated missing `ai-skills.json` generated file) — not caused by this change | | Local render (`pnpm dev:docs`) | All three pages return 200; new copy, nav entry, and all links/anchors verified to resolve | ### Proof: Reviewers should believe: the security landing page and regions guide now list GDPR/ISO 27001/DDoS coverage that was previously missing, and the new GDPR guide renders correctly with working links, where before it 404'd. ### Before & After **`/docs/guides/security`** — ISO 27001, GDPR, and DDoS paragraphs now present: | [Before (production)](https://supabase.com/docs/guides/security) | [After (PR preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security) | | ----------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | |  |  | **`/docs/guides/platform/regions`** — new "Data residency" section: | [Before (production)](https://supabase.com/docs/guides/platform/regions) | [After (PR preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/platform/regions) | | --------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | |  |  | **`/docs/guides/security/gdpr-compliance`** — net-new page, no production URL exists yet (404 before this PR): | Before (production) | [After (PR preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security/gdpr-compliance) | | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | | |  | ### Test plan ```text - [ ] Visit /docs/guides/security — confirm ISO 27001, GDPR, and DDoS paragraphs render under the right headings - [ ] Visit /docs/guides/security/gdpr-compliance — confirm it renders and appears in the sidebar under Compliance (next to SOC 2, HIPAA) - [ ] Visit /docs/guides/platform/regions — confirm the new "Data residency" section renders before "General regions" - [ ] Confirm links resolve: /docs/guides/security/gdpr-compliance, /docs/guides/platform/regions#specific-regions, /legal/dpa, /dashboard/org/_/documents ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation - Added a GDPR Compliance entry to the Compliance navigation. - Updated security documentation with ISO 27001 certification details, clearer GDPR guidance, and expanded protection information. - Clarified regional data residency guidance, including primary project data and GDPR considerations. - Made minor wording and formatting improvements to the GDPR compliance guide. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
a0cec24f49 |
Remove references to fly (#48648)
## Context As per PR title - should not have any visual nor functional change <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Changes** - Standardized infrastructure, region, and database configuration around AWS-based environments. - Removed Fly.io-specific region and provider options from project creation, instance sizing, and infrastructure settings. - Enabled disk validation, spend-cap eligibility, backup restoration, and extension setup consistently across supported projects. - Updated billing and region displays to use the applicable AWS configuration. - **Bug Fixes** - Corrected project-specific restrictions that could incorrectly hide configuration and billing controls. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8e3e14f198 |
Joshen/fe 4064 add a toast callout for feature preview (#48645)
## Context Adds a banner toast for the database connections feature preview <img width="315" height="322" alt="image" src="https://github.com/user-attachments/assets/8caaab88-10a0-4a06-b678-25fc9c44dd81" /> ## Other changes As the observability page currently has a number of banner toasts (metrics API, unified logs, index advisor for query performance), am opting to REMOVE the metrics API's banner toast by virtue of how long its been around for. Mainly to prevent over stacking of banner toasts as it can be annoying. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a dismissible Database Connections banner with SQL examples and a link to its feature preview. * Banner dismissal and CTA interactions are now tracked. * Dismissed banners can reappear when reintroduced. * **Bug Fixes** * Banners are hidden after the feature is enabled or dismissed. * Improved banner handling to prevent duplicate active banners. * **Changes** * Replaced the Metrics API banner with the Database Connections banner. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
94bc3f8d07 |
docs(csharp): add C# snippets (#48537)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added C# examples across API, authentication, database, Realtime, and Storage guides. * Expanded authentication coverage for passwordless, phone, anonymous, identity linking, SSO, sign-out, and social login providers. * Added database examples for queries, functions, joins, JSON, arrays, search, PostGIS, and custom schemas. * Added Realtime examples for broadcasts, presence, subscriptions, and database changes. * Added Storage examples for buckets, uploads, downloads, transformations, CDN purging, and resumable transfers. * Included C# error-handling guidance and relevant reference links. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5c5d7bcc63 |
docs: fix quickstart catalog gaps (#48618)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. Getting Started page is the most visited page in the docs at the moment: https://supabase.com/docs/guides/getting-started. Looking at all 19 guides, they appear to have drifted apart because there was never a written standard for what a quickstart must contain. Additionally, we are missing some frameworks, languages, and ORMs quickstarts. Phase 1 (this PR) fixes broken numbering, duplicated steps, and dead-end pages. Later phases bring all 19 guides into line with a single "definition of done" contract (error handling in samples, env vars everywhere, consistent Connect-panel pattern). The end goal is that every quickstart, regardless of framework, gives the same complete, trustworthy path from zero to a working app. ## What is the new behavior? 1. SvelteKit and Hono cards added to the [homepage grid](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs) (FrameworkQuickstarts.tsx). Only added the most popular missing frameworks to the grid. 2. [Rails](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#2-install-agent-skills-optional): Add missing second step (Agent Skills), add next steps at the end (point 6) 3. [Laravel](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#6-set-up-the-postgres-connection-details): Remove duplicated instruction to create project from step 6. 4. [Refine](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/refine#5-update-supabaseclient-with-environment-variables): In step 5, create .env file (VITE_SUPABASE_URL, VITE_SUPABASE_PUBLISHABLE_KEY), and the client reads them via import.meta.env, matching the Vite-based refine-supabase preset. 5. [Hono](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/hono#6-set-up-the-required-environment-variables) TODO resolved: In step 6, add the "Open Connect panel" Button with the generic api_settings.mdx partial call, identical to the Flask and Expo pattern. 6. Next steps added to the 9 guides missing it at the end of the guide, linking to the framework tutorial or Auth, UI components, data import, and Storage (Flutter, Kotlin, Laravel, Nuxt, RedwoodJS, Refine, Ruby on Rails, SolidJS, and Vue). 7. Remove 4 stale screenshots from RedwoodJS and Refine, along with their now-orphaned image assets under apps/docs/public/img/. The surrounding text already covers what they showed; they weren't Connect-panel screens, so the Button pattern didn't apply as a replacement. 8. Add [Supabase Agent Skills](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#4-install-agent-skills-optional) purpose and benefits for the user 9. Start all guides from creating Supabase project ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation - Added SvelteKit and Hono quickstarts with icons and documentation links. - Expanded Agent Skills guidance across framework quickstarts, including current authentication, SSR, and migration patterns. - Improved project creation, Connect panel, API configuration, and credential setup instructions. - Added framework-specific “Next steps” resources for Auth, database imports, Storage, UI components, and libraries. - Clarified PostgreSQL SSL, password encoding, connection, and environment-variable requirements. - Replaced outdated screenshots with clearer setup guidance and relevant examples. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9006e33f11 |
Add categories for feature previews (#48641)
## Context Given that our number of feature previews have been expanding, am opting to group them into categories for easier understanding of the context of each feature preview. Ideally we're able to tag all feature previews into categories (or add more categories), but leaving the unclassified ones under "others" for now <img width="936" height="661" alt="image" src="https://github.com/user-attachments/assets/b48bd9a2-fe33-4cb0-9288-1cd9c8264da0" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Feature previews are now organized into expandable categories. * Observability and database previews are grouped for easier browsing. * Uncategorized previews remain available under an “Others” section. * Existing feature selection options and sorting behavior are preserved. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
76257f164b |
fix(studio): align storage row icon weight (#48480)
## What kind of change does this PR introduce? Bug fix stacked on #48478. ## What is the current behavior? Storage Explorer renders the custom closed-folder icon at `1.5` but leaves the Lucide open-folder icon at its default `2`. The duplicated file-picker implementation also uses a different set of stroke-width overrides. ## What is the new behavior? A shared `StorageRowIcon` renders loading, open and closed folder, image, audio, video and generic file icons at `1.5` across Storage Explorer, row editing and the bucket file picker. Test by comparing open and closed folders and file-type rows in Storage Explorer and the bucket file picker. | Before | After | | --- | --- | | <img width="524" height="336" alt="CleanShot 2026-08-03 at 18 38 06@2x" src="https://github.com/user-attachments/assets/15eb8b9f-69fc-4eee-8428-d7ec26dce8dc" /> | <img width="522" height="328" alt="CleanShot 2026-08-03 at 18 39 20@2x" src="https://github.com/user-attachments/assets/17b7dddd-8d36-421c-8356-c9c1bd7456e8" /> | | _Thicker image and file icon compared to folder icon_ | _Every icon has the same stroke thickness_ | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Standardized file, folder, media, and loading icons across storage views. * Improved visual consistency with unified icon sizing, styling, and stroke width. * **Tests** * Added coverage for loading, folder, media, and generic file icon states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fc69c45985 |
Bring database connections to feature preview (#48638)
## Context As per PR title - brings Database Connections into feature preview Should be working for both hosted + self-host/local Also adjusts existing feature previews to remove "New" - Platform webhooks - Temporary database access <img width="600" alt="image" src="https://github.com/user-attachments/assets/b18ae8ca-ce0b-4649-975c-e70749a87dcd" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Database Connections preview highlighting live activity, query blocking detection, session termination, and AI-assisted summaries. * Added access to project-specific observability connections from the preview. * Added a Database Connections entry to the observability menu when enabled. * **Improvements** * Updated feature previews and labels, including changes to “new” status indicators. * Added controls to manage Database Connections preview visibility. * **Bug Fixes** * Improved blocker detection so results respect the selected role filters. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3f5ac679e0 |
fix(studio): redirect to feature preview route after enabling (#48637)
Enabling a feature preview that has a route (e.g. Column-level
privileges) closed the modal but never navigated to the feature's page
on the TanStack runtime (local + staging). The modal closed itself via a
nuqs query-param update *and* called `router.push` — the queued nuqs
flush navigates to the pathname it captured before the push, landing
after the redirect and reverting it. The Next runtime was unaffected
because the stock nuqs pages adapter patches the URL shallowly via the
history API instead of navigating.
**Changed:**
- When the enabled preview has a `getRoute`, skip the explicit
`toggleFeaturePreviewModal(false)` — `router.push(route)` navigates
without the `featurePreviewModal` param, which is what closes the modal.
One URL update instead of two racing ones; works on both runtimes.
- Previews without a route keep the explicit close (unchanged behavior).
## To test
- On a project page, open Feature Previews (avatar menu), select
**Column-level privileges**, click **Enable feature** → modal closes and
you land on `/project/{ref}/database/column-privileges` with the "We've
taken you to where you can try it out." toast (no bounce back to the
previous page)
- Repeat with **Disable Advisor rules** → lands on
`/project/{ref}/advisors/rules/security`
- Enable a preview without a route (e.g. **PG Delta Diff**) → modal
closes, stays on the current page, "It's now active across the
dashboard." toast
- Disable a preview → modal stays open, "disabled" toast, no navigation
- Verified locally on the TanStack runtime; worth a quick click-through
on the Vercel preview (Next runtime) too
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved feature activation navigation to prevent conflicting URL
updates.
* Non-route features continue to close the preview modal and display the
activation confirmation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
|
||
|
|
73c9dbfa52 |
fix(studio): standardise custom icon weight (#48478)
## What kind of change does this PR introduce? Bug fix and internal tooling update. Resolves FE-3472. ## What is the current behavior? Custom Studio icons use inconsistent source stroke widths, and some child-level styling prevents component props from overriding them. Mixed custom and Lucide icon sets can therefore appear uneven. ## What is the new behavior? Custom stroke icons use a root-level `stroke-width="1.5"`; fill-only logos use `stroke="none"`. The build validates that contract and regenerated components preserve existing exports and props. Studio applies the same `1.5` weight across Reports categories and uses one shared destination icon mapping in the replication selector, destination rows and diagram. | Before | After | | --- | --- | | <img width="418" height="516" alt="56398" src="https://github.com/user-attachments/assets/6afa7042-e6be-40e7-9911-af2f61238c9d" /> | <img width="390" height="550" alt="CleanShot 2026-07-30 at 17 12 37@2x" src="https://github.com/user-attachments/assets/870f49cf-c8fa-40db-8be8-2eb5f264ff4a" /> | | <img width="510" height="734" alt="CleanShot 2026-07-30 at 17 19 28@2x" src="https://github.com/user-attachments/assets/a5b2c088-dcd2-4907-976b-5820794d06e3" /> | <img width="554" height="742" alt="CleanShot 2026-07-30 at 17 16 06@2x" src="https://github.com/user-attachments/assets/ed3a77c4-5d94-4ca7-b9e4-1403b725a981" /> | ## Testing At 100% zoom, compare custom and Lucide icon weight in: - Reports: **Add your first chart** and **Add block** - Database > Replication: the destination selector, destination rows and replication diagram - Command menu (`⌘K`): **Search Database Tables**, **Search RLS Policies**, **Search Edge Functions** and **Search Storage** - Authentication > Users: right-click a user row and compare the context-menu icons - Database > Schema Visualizer: open a table node overflow menu - A paused project: **Export your data > Download backups** <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added consistent destination icons across replication panels, rows, and diagrams. * Updated instance health and metric icons for clearer identification. * Standardized icon stroke weight and reduced default icon stroke thickness. * **Documentation** * Clarified custom icon requirements, default properties, and validation guidance. * **Bug Fixes** * Improved consistency of icon rendering across replication destinations and reports. * **Tests** * Added coverage for icon SVG validation and replication destination icon rendering. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
99e66029c8 |
docs: document the supabase-js /tracing opt-in subpath (#48529)
## What kind of change does this PR introduce? Documentation update for `apps/docs/content/guides/monitoring-and-debugging/client-side-tracing.mdx`. As of `@supabase/supabase-js` 2.112.0 (supabase/supabase-js#2583), the OpenTelemetry integration moved out of the main bundle into an opt-in subpath. Enabling trace propagation now takes two steps: `import '@supabase/supabase-js/tracing'` at the application entry point, plus the existing `tracePropagation: true` client option. Guide changes: - Requirements: documents the subpath import (2.112.0+), the loud-resolution behavior when `@opentelemetry/api` is missing, the one-time warning when the runtime isn't loaded, the version note for 2.106.0–2.111.x (no import there), and that the CDN/UMD build does not support tracing. - Both code samples now start with the subpath import. - Troubleshooting: new first check (runtime not loaded → one-time console warning), updated `@opentelemetry/api` semantics per version, new CDN/UMD entry. The JS reference (`typeSpec.json`) is regenerated automatically by the docs-update pipeline from the supabase-js spec and is not touched here. **Timing note:** merge once 2.112.0 is promoted to `latest` (currently on `beta`/`canary`) so the guide doesn't get ahead of the stable release. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated client-side tracing guidance for `@supabase/supabase-js` 2.112.0 and later. * Added setup examples for the required one-time opt-in import. * Clarified behavior when tracing dependencies are missing and documented CDN usage limitations. * Expanded troubleshooting guidance for runtime loading, module resolution, and UMD usage. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
2c53ca4a79 |
Support listing and reading custom reports from Assistant (#48530)
## Context This is pre-requisite work for adding support to managing custom reports from the Assistant. Planning to break this into a number of PRs, briefly - Adding read support for custom reports - Adding write support for custom reports - Adding run support for custom reports - Should be able to infer data from the results then This PR starts with adding support for listing and reading custom reports from the Assistant ## Other changes involved - Updates setting up of the home page report to have better title and description - Swaps the variant of the ToggleGroup in the SQL block for custom reports as the default variant blends into the background color of the PopoverContent ## To test - [ ] Assistant should be able to list custom reports + read its contents <img width="428" height="755" alt="image" src="https://github.com/user-attachments/assets/6a15b660-c0ee-4a06-984c-87eff3943eec" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added AI-assisted tools to list reports and retrieve report details, including chart counts, layouts, configurations, and SQL-backed chart information. - Added clearer empty-state messaging when no snippets are available. - **Improvements** - New homepage reports now use the name “Homepage Report” and include a descriptive project-home summary. - Updated query controls with refreshed visual styling. - Improved content requests to support additional request context. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
022b374f2d |
show Stripe Projects errors inline (#48472)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Stripe Projects confirmation failures only appear in a toast. The existing **Unable to load authorization** Admonition is a separate error state shown when the account request itself cannot be loaded. ## What is the new behavior? Confirmation failures remain visible below the authorisation actions, clear on retry, and do not also trigger a toast. They use the shared `InterstitialActionError`. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Authorize Stripe Projects Supabase" src="https://github.com/user-attachments/assets/83cb3144-9ddb-46b7-bfce-970497be61e2" /> | <img width="1024" height="759" alt="Authorize Stripe Projects Supabase" src="https://github.com/user-attachments/assets/bccedde9-9935-457b-a980-0c80499f2f27" /> | ## To test These instructions visually check the after state on this branch. Opening an invalid `ar_id` without the hardcodes only exercises the existing load-error Admonition, which this PR does not change. ### After on this branch 1. In `apps/studio/pages/partners/stripe/projects/login.tsx`, replace the `confirmationError` assignment with: ```tsx const confirmationError = 'Failed to authorize Stripe Projects: Test error' ``` 2. In the same file, replace the block beginning with `const linkedOrg` and ending with `interstitialDescription` with: ```tsx const linkedOrg = { name: 'Example Organization' } const emailMatches = true const displayName = primaryEmail ?? username ?? 'reviewer@example.com' const isPending = false const isConfirmed = false const isConfirming = false const isError = false const showAuthorizationState = true const interstitialDescription = 'This will create an organization on your behalf in Supabase' ``` 3. While signed in locally, open `http://localhost:8082/partners/stripe/projects/login?ar_id=test`. 4. Confirm the error appears below **Authorize Stripe Projects** and **Cancel**. No real Stripe request is required. 5. Revert both temporary edits. ### Before on master (optional) 1. Check out `master`. 2. In `apps/studio/pages/partners/stripe/projects/login.tsx`, replace the block beginning with `const linkedOrg` and ending with `interstitialDescription` with the same block from step 2 above. Do not add `confirmationError`. 3. While signed in locally, open `http://localhost:8082/partners/stripe/projects/login?ar_id=test`. 4. Click **Authorize Stripe Projects**. 5. Confirm the failed confirmation appears in a toast beginning **Failed to confirm account request**. 6. Revert the temporary edit before changing branches. ## Additional context Stacked on #48471. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Bug Fixes** * Authorization errors during Stripe Projects login are now displayed inline in both authorization flows. * Authorization remains available after a failed confirmation attempt. * Failed authorization requests no longer trigger an additional toast notification. * Previous errors are cleared when retrying authorization. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c0f1ef51fb |
feat(docs): migrate resources and getting-started to ContentListings (#48517)
## What kind of change does this PR introduce? Docs update / follow-up to #48379. ## What is the current behavior? `/guides/resources` and `/guides/getting-started` hand-roll `GlassPanel` grids in MDX. They look like ContentListings cards after the chrome PR, but they do not use the shared data files, so they miss PostHog `docs_content_listing_clicked` telemetry and the CONTRIBUTING contribution path. ## What is the new behavior? Those pages use `<ContentListings id="…" />` backed by `resources.data.ts` and `getting-started.data.ts`, same pattern as storage. - Section-level `$Show` wrappers stay for framework / web / mobile blocks - Nimbus stays a `$Partial` behind `$Show` - New optional per-item `feature` field gates SDK links (e.g. Flutter / Swift / Kotlin) without splitting whole sections - CONTRIBUTING notes when to use `feature` vs a partial-level `$Show` ## To test Compare the following against `master`: - [Resources](https://docs-git-dnywh-docs-content-listings-resources-239158-supabase.vercel.app/docs/guides/resources): overview, migrate, and postgres grids; icons in light/dark - [Getting started](https://docs-git-dnywh-docs-content-listings-resources-239158-supabase.vercel.app/docs/guides/getting-started): overview, use cases, framework quickstarts, web demos, mobile tutorials; nimbus partial when enabled - Click a card and confirm `docs_content_listing_clicked` fires with the expected `listingId` Everything should look and feel the same. It’s just that we’re using `ContentListings` instead of `GlassPanel` grids. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added centralized Getting Started and Resources content listings, including quickstarts, demos, tutorials, migration guides, and Postgres resources. - Added feature-based visibility controls for individual content listing items. - **Improvements** - Disabled content is now automatically hidden from documentation pages and generated Markdown. - Pages and sections with no available content are omitted entirely. - External documentation links are more secure. - Updated contribution guidance with instructions and examples for feature flags. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e7796315d2 |
fix sheets stealing focus (#48521)
## What kind of change does this PR introduce? Bug fix. Resolves DEPR-539. ## What is the current behavior? When a focused child unmounts, Radix can move focus to the Sheet wrapper and break the expected tab order. Several callsites suppress the wrapper's tabindex individually. ## What is the new behavior? Sheet still focuses its first interactive child when opened, but the wrapper itself is no longer focusable by default. Callers can opt in with an explicit `tabIndex` when needed. ## Additional context ### Testing Compare this Studio experience on both this branch and `master`: 1. Open any project with an Edge Function. 2. Go to **Edge Functions**, open the function, then click **Test**. 3. Under **Headers**, click **Add Headers**. Click the first header key input, then Tab slowly through the header inputs and remove buttons. On `master`, focus can jump to the whole Sheet. On this branch, focus stays on the controls in order. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved keyboard focus behavior across sheets and panels. * Sheets now focus the first available interactive element when opened, without adding unnecessary focus targets. * Preserved support for programmatic focus and prevented focus from unexpectedly moving to the sheet when focused content is removed. * Updated authentication, integrations, connection, logging, storage, and other sheet interfaces consistently. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7a77760a10 |
fix(studio): confirm before discarding dirty replication destination forms (#48522)
## What kind of change does this PR introduce? Bug fix (dirty form dismissal for Replication destination sheets), plus small docs/skill updates so agents pick up the existing modality pattern. ## What is the current behavior? Closing the Add/Edit destination sheet (Cancel, Escape, or backdrop) discards in-progress form state with no confirm. Same for the nested Create publication sheet. ## What is the new behavior? Dirty closes go through `useConfirmOnClose` + `DiscardChangesConfirmationDialog`, matching other Studio sheets. Successful submit still closes without prompting. Also: skills + `forms.mdx` now point at Modality “Dirty form dismissal”. | After | | --- | | <img width="1024" height="759" alt="Replication Database Chisel Toolshed Supabase" src="https://github.com/user-attachments/assets/6f568a2a-c76b-442a-b592-d638bb36adc4" /> | ### How to test 1. Studio → Database → Replication → **Add destination** (any pipelines type with access). 2. Change a field so the form is dirty. 3. Try Cancel, Escape, and backdrop click → discard dialog appears; **Keep editing** stays open; **Discard changes** closes. 4. Submit successfully with a valid config → sheet closes with no discard dialog. 5. Repeat for **Edit destination** from a destination row menu. 6. Optional: Add destination → create a new publication from the publication picker → dirty that nested sheet and dismiss the same way. 7. Optional: Add destination → Read Replica → change region → dismiss → discard dialog; deploy still closes without prompting. ## Additional context Sheet owns the close guard; forms report dirty via a ref because RHF lives in the child. Nested `NewPublicationPanel` wires the guard locally. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added unsaved-changes tracking to replication destination and publication forms. - Added confirmation prompts before closing forms with unsaved changes via Cancel, Escape, or backdrop dismissal. - Forms now reset appropriately after successful submission or confirmed dismissal. - **Documentation** - Updated form and UI pattern guidance to document dirty-form dismissal behavior for sheets and dialogs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
eef0f57309 |
fix(studio): clarify Storage columns keyboard focus and selection (#48222)
## What kind of change does this PR introduce? Accessibility / UX fix ([DEPR-630](https://linear.app/supabase/issue/DEPR-630)). ## What is the current behavior? In Storage **As columns** view, keyboard select is unclear: the checkbox stays hidden until hover, so Tab/Space selection is hard to see. The row actions (three dots) menu also shows a browser default blue outline on Tab. ## What is the new behavior? Same icon/checkbox swap as list/hover, but also on keyboard focus: - Checkbox replaces the icon on hover, `:focus-within`, and when selected (no layout shift) - Checkbox becomes visible when focused via keyboard (without needing hover) - Row gets an inset outline while the checkbox is focused - Folders have no checkbox (non-focusable spacer only) - Row actions trigger uses `focus-ring` instead of the browser blue outline | Before | After | | --- | --- | | <img width="1046" height="362" alt="CleanShot 2026-07-31 at 14 37 47@2x" src="https://github.com/user-attachments/assets/9b827627-17e6-49a6-87a3-1253b4cef1da" /> | <img width="1046" height="390" alt="CleanShot 2026-07-31 at 14 37 13@2x" src="https://github.com/user-attachments/assets/2fd2b426-a8e2-4fda-b1ba-4df728b7b2f1" /> | | _Checkbox focussed but not visually shown_ | _Checkbox focussed and visually shown_ | ## To test 1. Open the **Studio preview** for this PR. 2. Go to **Storage → Files** → open a bucket with several files. 3. Set view to **As columns**. 4. Tab until a **file** checkbox is focused. **Expect:** - Icon is replaced by the checkbox (same slot; neighbouring row icons should not look shifted) - Checkbox visible without hovering - Row shows an inset outline 5. Press **Space** to select. Checkbox stays in the icon slot; selection background applies. 6. Hover another file. Same icon to checkbox swap as before. 7. Tab to the three-dot actions control on a row. Expect the shared focus ring (not a blue browser outline); the menu icon should become visible. 8. Folders: no checkbox in the tab order; click icon/name still opens the folder. 9. Smoke **As list**. Same swap behaviour. ## Additional context From Kemal's DEPR-621 review. |
||
|
|
f7454cf94e |
feat(studio): oauth impersonation warning on authorize (#48162)
## What kind of change does this PR introduce? Feature + docs. Stacked on #48161 (logo contract / [DEPR-604](https://linear.app/supabase/issue/DEPR-604/define-connect-logo-asset-and-variant-contract)). ## What is the current behavior? After #48161, curated logos only resolve from allowlisted `redirect_uri` hosts. A requester can still present a trusted partner **name** (e.g. Claude) while redirecting to an unrelated remote host; the UI shows Supabase alone but does not call out the mismatch. ## What is the new behavior? - Shows a caution admonition when the requester name looks like a trusted partner (Claude, Cursor, ChatGPT/OpenAI, Perplexity) but `redirect_uri` is a **remote** host outside that partner's allowlist. - Skips localhost / loopback redirects for the caution (common for local MCP clients); those still get curated logos when the name matches a trusted partner. - Highlights the footer redirect URL in warning colour when the caution is shown. - Documents the behaviour in the Connect interstitials pattern. ### To test Real MCP clients (Claude, Cursor, etc.) only send users to **production** `/authorize`, so you cannot drive a local or preview Studio build from those tools. Use a Network override instead: 1. Start Studio and sign in (`pnpm dev:studio`, or use the [Vercel preview](https://studio-staging-git-danny-oauth-impersonation-warning-supabase.vercel.app/)). 2. Open `/dashboard/authorize?auth_id=foo` (any `auth_id` is fine; the real response may 404) ([Vercel preview](https://studio-staging-git-danny-oauth-impersonation-warning-supabase.vercel.app/dashboard/authorize?auth_id=foo)). 3. DevTools → **Network** → find `GET …/platform/oauth/authorizations/foo` (or whatever id you used). 4. Right-click → **Override content** (enable Local Overrides / pick a folder if prompted). 5. Paste one of the payloads below (status **200**), save, then reload the authorize page. 6. Keep `expires_at` in the future so the request does not look expired. #### Impersonation caution (trusted name + remote non-allowlisted redirect) Expect: - Supabase alone (no curated Claude mark) - Caution: “Redirect does not match this app name” - Footer redirect URL in warning colour ```json { "name": "Claude", "website": "https://claude.ai", "icon": null, "domain": "claude.ai", "redirect_uri": "https://evil.com/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "dynamic" } ``` | Preview | | --- | | <img width="764" height="958" alt="Authorize Claude Supabase" src="https://github.com/user-attachments/assets/e6eee016-5710-41ba-9925-87511e009e22" /> | #### Localhost MCP: no caution Expect curated Claude + Supabase pair (name match + loopback), **no** caution, normal footer colour. Local MCP clients often use loopback redirects. ```json { "name": "Claude", "website": "https://claude.ai", "icon": null, "domain": "claude.ai", "redirect_uri": "http://127.0.0.1:42813/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "dynamic" } ``` | Preview | | --- | | <img width="764" height="958" alt="Authorize Claude Supabase" src="https://github.com/user-attachments/assets/79f36865-3c8e-43e5-9490-24288efc74aa" /> | #### Legitimate curated partner: no caution Expect curated Cursor + Supabase pair, no admonition, normal footer colour. ```json { "name": "Cursor", "website": "https://cursor.com", "icon": null, "domain": "cursor.com", "redirect_uri": "https://cursor.com/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "dynamic" } ``` | Preview | | --- | | <img width="764" height="958" alt="56164" src="https://github.com/user-attachments/assets/412333a3-a74f-42eb-9f63-d56b6a26bf91" /> | #### Unrelated name + remote redirect: no caution Expect Supabase alone (no icon), no admonition. ```json { "name": "Acme Tools", "website": "https://evil.com", "icon": null, "domain": "evil.com", "redirect_uri": "https://evil.com/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "dynamic" } ``` | Preview | | --- | | <img width="764" height="958" alt="Authorize Acme Tools Supabase" src="https://github.com/user-attachments/assets/dab24817-5c26-4aa1-a447-796c4af5868b" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - Added an OAuth caution when a requester name matches a known partner but uses an unapproved remote redirect host. - Improved trusted partner logo selection for localhost/loopback redirects while preserving safe fallbacks for untrusted redirects. - **Documentation** - Updated Connect interstitial guidance for redirect mismatches and localhost/loopback behavior. - **Tests** - Expanded coverage for caution visibility, messaging, localhost logo pairing, and trusted redirect scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2b26da360e |
show API and AWS authorization errors inline (#48471)
## What kind of change does this PR introduce? Bug fix and design-system update. ## What is the current behavior? API authorisation and AWS Marketplace action failures use transient toasts. The inline action-error treatment introduced for organisation invitations is implemented locally. ## What is the new behavior? Action failures remain visible below their actions and clear on retry or organisation change. This PR adds a shared `InterstitialActionError` component, updates the connect-interstitial guidance and demo to use it, and retroactively applies it to `OrganizationInvite`. Mutation errors are read directly from their mutation hooks rather than copied into component state. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Authorize API Access Supabase" src="https://github.com/user-attachments/assets/9520aff3-496d-44b1-b5b5-02b331872e32" /> | <img width="1024" height="759" alt="Authorize API Access Supabase" src="https://github.com/user-attachments/assets/2d09e337-573a-45b5-80ac-7c546ed1401d" /> | | <img width="1024" height="759" alt="Link AWS Marketplace Supabase" src="https://github.com/user-attachments/assets/bb1a4581-0399-432a-8037-d84ab15ecc4b" /> | <img width="1024" height="759" alt="Link AWS Marketplace Supabase" src="https://github.com/user-attachments/assets/f9d43cd9-c661-42ed-91c0-e45ccb9c19f5" /> | _Note since taking that AWS screenshot: the error message now replaces the prior footer text. I.e. “Learn more about billing through AWS.” is now gone when an error message is present._ ## To test ### AWS Marketplace For a visual check with local Studio running: 1. In `apps/studio/components/interfaces/Organization/CloudMarketplace/AwsMarketplaceOnboarding.tsx`, immediately before `if (!buyerId)`, temporarily add: ```tsx return ( <AwsMarketplaceInterstitial> <div className="flex flex-col gap-5"> <InterstitialAccountRow displayName="reviewer@example.com" /> <OrganizationSelector organizations={[ { name: 'Example Organization', slug: 'example-organization', plan: { id: 'pro', name: 'Pro' }, } as Organization, ]} selectedSlug="example-organization" disabled onSelect={() => undefined} /> <div className="flex flex-col gap-5"> <div className="flex flex-col gap-2"> <Button variant="primary" block> Link organization </Button> <InterstitialActionError error="Failed to link organization: Test error" /> </div> <p className="text-center text-xs text-foreground-lighter text-balance"> <InlineLink href={`${DOCS_URL}/guides/platform/aws-marketplace`}> Learn more </InlineLink>{' '} about billing through AWS. </p> </div> </div> </AwsMarketplaceInterstitial> ) ``` 2. Open `http://localhost:8082/aws-marketplace-onboarding?buyer_id=test` while signed in. 3. Confirm the error appears below **Link organization** with a divider. Remove the temporary return before committing anything. ### API authorization For a visual check with local Studio running: 1. In `apps/studio/components/interfaces/ApiAuthorization/ApiAuthorization.Valid.tsx`, immediately before `if (isLoading)`, temporarily add: ```tsx return ( <ApiAuthorizationMainView approvalState="indeterminate" form={form} requester={{ name: 'Test App', website: 'https://example.com', icon: null, domain: 'example.com', scopes: [], expires_at: '2099-01-01T00:00:00.000Z', approved_at: null, registration_type: 'static', }} organizations={{ _tag: 'success', organizations: [ { name: 'Example Organization', slug: 'example-organization' } as Organization, ], }} requestedOrganizationSlug={undefined} actionError="Failed to authorize request: Test error" onOrganizationChange={() => undefined} onApprove={() => undefined} onDecline={() => undefined} /> ) ``` 2. Open `http://localhost:8082/authorize?auth_id=test` while signed in. 3. Confirm the error appears below the authorisation actions with a divider. Remove the temporary return before committing anything. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added consistent inline error messaging for authorization, organization invitations, and AWS Marketplace onboarding. * Error messages now appear within the relevant interstitial and replace supporting footer content until resolved. * Retry and action buttons remain available after failed operations. * **Bug Fixes** * AWS Marketplace linking failures no longer trigger toast notifications. * Billing guidance is hidden while an onboarding error is displayed. * **Tests** * Added coverage for authorization, cancellation, and AWS Marketplace failure states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
3a3661019f |
docs: update architecture diagram and references from Kong to Envoy (#48557)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This is a docs update. The shared architecture diagram and several docs pages still described Kong as Supabase's API gateway, even though the hosted platform has run Envoy since 2025. Both diagram variants are rebuilt with real, accessible text — the originals rendered every label as an outlined vector path with zero `<text>` elements — so the gateway name can be kept current going forward, and the platform-facing prose that named Kong directly is updated to Envoy. Closes DOCS-1262. ## What is the current behavior? - The architecture diagram (used on the Architecture overview, Auth architecture, Self-hosting Docker, and Contributing guide pages) shows "KONG / docs.konghq.com" as the gateway box - The Architecture overview page has a "Kong (API gateway)" component section - The Auth architecture page states "Kong API gateway. This is shared between all Supabase products." - `README.md` and `apps/docs/public/humans.txt` credit Kong instead of Envoy ## What is the new behavior? - Rebuilt `supabase-architecture.svg` and `supabase-architecture--light.svg` with real `<text>` elements; the gateway box now reads "ENVOY / envoyproxy.io" with identical layout, colors, and shadows otherwise - Updated the diagram alt text and the "Kong (API gateway)" section (now "Envoy (API gateway)", with the correct docs link, license, and language) on the Architecture overview page - Updated the "Kong API gateway" bullet and diagram alt text on the Auth architecture page - Updated the Kong credit to Envoy in `README.md` and `apps/docs/public/humans.txt` **Intentionally excluded:** - Self-hosted Docker Compose pages (`docker.mdx`, `enable-mcp.mdx`, `self-hosted-auth-keys.mdx`, `self-hosted-envoy.mdx`, `self-hosted-functions.mdx`, `self-hosted-proxy-https.mdx`) — these describe the self-hosted stack, which still defaults to Kong today and is already owned by an open PR (#48153) that flips that default - `i18n/README.*.md` (29 files) — translation risk without native-speaker review; only the English `README.md` was updated ## Open questions - [ ] #48153 merges and the self-hosted default actually flips to Envoy — once it does, revisit the self-hosting Docker Compose pages excluded from this PR and the self-hosting-analytics reference TODO - [ ] Confirm whether all legacy platform instances have fully migrated to Envoy — until then, this PR's wording says "Envoy" without claiming Kong is gone everywhere (some legacy instances may still silently be on Kong) - [ ] Current Envoy response header names confirmed for the logs guide TODO (`x-kong-proxy-latency` / `x-kong-upstream-latency`) - [ ] i18n README translations (29 files) follow up separately with native-speaker review ## Additional context - Verification: rendered both new SVGs with `rsvg-convert` and visually diffed against the originals — layout, spacing, colors, and shadows are pixel-equivalent; only the top-box label text changed | Check | Result | | --- | --- | | `rsvg-convert` render, dark variant | pass — diagram unchanged except gateway label | | `rsvg-convert` render, light variant | pass — diagram unchanged except gateway label | | Preview URL, Architecture overview | pass — 200 | | Preview URL, Auth architecture | pass — 200 | ### Before & After #### [Architecture overview](https://supabase.com/docs/guides/getting-started/architecture) | [Before (production)](https://supabase.com/docs/guides/getting-started/architecture) | [After (PR preview)](https://docs-git-nikrichers-docs-1262-architecture-docs-84e339-supabase.vercel.app/docs/guides/getting-started/architecture) | | --- | --- | |  |  | #### [Auth architecture](https://supabase.com/docs/guides/auth/architecture) | [Before (production)](https://supabase.com/docs/guides/auth/architecture) | [After (PR preview)](https://docs-git-nikrichers-docs-1262-architecture-docs-84e339-supabase.vercel.app/docs/guides/auth/architecture) | | --- | --- | |  |  | ### Test plan - [ ] Diagram renders correctly in both light and dark mode on the preview - [ ] "Envoy (API gateway)" section reads correctly on the Architecture overview page - [ ] Auth architecture bullet reads "Envoy API gateway" - [ ] The two TODO-marked follow-ups (logs guide, self-hosting-analytics) are acceptable to leave for later rather than block this PR --------- Co-authored-by: Nik Richers <nik@validmind.ai> Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
e88a3723e1 |
feat(studio): add PostHog session replay with masked-by-default policy (#48515)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Telemetry feature. ## What is the current behavior? - Session replay is off, and nothing in the code keeps it off. - `packages/common/posthog-client.ts` sets no recording config at all. - So PostHog's project setting alone decides, for every app sharing that project. - Studio, www and docs share one project. - Studio shows customer data almost everywhere: SQL editor, table rows, connection strings, API keys. - posthog-js masks inputs by default. It does not mask rendered text. - [GROWTH-1055](https://linear.app/supabase/issue/GROWTH-1055) ## What is the new behavior? - `posthogClient.init()` takes a masking config, and disables recording when it gets none. - Studio passes one behind `NEXT_PUBLIC_POSTHOG_SESSION_REPLAY`. - Every other app passes nothing, so it never loads the recorder. - Studio masks all text and all inputs. - `data-ph-capture="true"` opts one element's text back in. Unused so far. - Canvas is blocked, because it records as images that text masking cannot reach. - Query strings and fragments are stripped from recorded URLs, where auth callbacks carry tokens. - Request and response bodies are never recorded. - Console logs are never recorded, since masking only reaches DOM text. - Masking is set in code, so PostHog's settings cannot loosen it. - Consent gating is unchanged. Nothing records before a user accepts. ## Additional context - Recording needs three things: this env var, the PostHog project toggle, and user consent. - All three are off or unset, so merging this changes nothing at runtime. - `NEXT_PUBLIC_POSTHOG_SESSION_REPLAY` goes into Vercel on Preview scope first, to test on a preview build. - Production scope comes later, once we are ready to record there. - `NEXT_PUBLIC_*` is inlined at build time, so each scope needs a rebuild afterwards. - Text inside HTML attributes (`title`, `alt`, `href`) is still recorded as-is. - posthog-js exposes no hook for masking attributes, so covering it needs `ph-no-capture` per component. - Staging has no server-side masking config, so that is where this gets verified. - Plan: enable recording on staging, verify masked text on a preview, then decide on production. - Network timing stays on for the dashboard performance work. Payloads stay off. - Tests cover both masking functions and the config values. ## Screenshots https://github.com/user-attachments/assets/aa064a04-f977-4453-a3da-2fe0cdcead08 <img width="889" height="651" alt="CleanShot 2026-07-31 at 10 13 43" src="https://github.com/user-attachments/assets/f1d07946-fd68-42b2-89f1-d201bc605638" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Added privacy-focused session replay for Studio. * Text and form inputs are masked by default, with explicit opt-in capture. * Network recordings remove query strings and fragments. * Headers, request bodies, canvas data, and console logs are excluded. * **Bug Fixes** * Improved whitespace and capture-attribute handling during masking. * Session replay remains disabled without a masking policy or explicit enablement. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ec64135f9d |
perf(pg-meta): scope column privileges query to a single table (#48553)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Performance improvement ## What is the current behavior? The column privileges page in Studio only ever renders one table, but the underlying query still `aclexplode`s every column in the whole schema and filters the result client-side. ## What is the new behavior? Adds a scoped SQL path that prunes `pg_class`/`pg_namespace` to the requested schema+table before exploding ACLs, gated behind the `pgMetaScopedIntrospection` flag, with a plan-guard test asserting `pg_class`/`pg_attribute` stay index-driven. Studio's query hook and cache keys now thread the selected table through so column-privilege invalidation and cold-load races are scoped correctly, and the page fetches per-table instead of per-schema. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Column privileges are now scoped to the selected schema and table for more accurate results. * Changing schemas automatically updates the table selection and refreshes the displayed privileges. * Privilege updates now refresh only the relevant schema, table, and column data. * Loading states are handled more accurately when no table is selected. * **Bug Fixes** * Improved consistency between scoped and unscoped column privilege results, including table-, column-, and grant-option privileges. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d47747477d |
docs(blog): add Introducing Supabase Evals launch post (#48505)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Adds a new blog post announcing the open-source `supabase/evals` benchmark, published at `/blog/introducing-supabase-evals` (date 2026-07-31) - Adds the post's images (`og.png`, `thumb.png`, and an inline benchmark-results chart) under `apps/www/public/images/blog/introducing-supabase-evals/` ## What is the current behavior? N/A. No existing post for this launch. ## What is the new behavior? - New MDX post `apps/www/_blog/2026-07-31-introducing-supabase-evals.mdx`, author `matt_rossman`, category `product` - Post covers what Supabase Evals is, why we built it, how the benchmark and regression suites work, key findings, and where agents struggle ## Additional context - Opened as a draft. Content is still under review in Notion, so this is not ready to merge yet. - Part of the Introducing Supabase Evals launch (Tier 2, target 2026-07-31). - Images are placeholders pending final assets from Brand Design if needed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new blog post introducing Supabase Evals, an open-source benchmark for evaluating AI coding agents on real Supabase tasks. * Described how evaluations run, how scoring works, retry behavior, update cadence, and common failure areas. * Included links to explore results and shared plans for expanding scenarios, improving scoring rigor, and adding feedback capabilities. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <ana1337x@users.noreply.github.com> Co-authored-by: Matt Rossman <22670878+mattrossman@users.noreply.github.com> |
||
|
|
320111b06b |
fix(docs): replace hardcoded heading tags in 4 shared components (#48456)
Closes DOCS-1261 _WAVE plugin shows headers creating jumps in hierarchy. Preview on the left:_ <img width="1022" height="417" alt="Screenshot 2026-07-29 at 2 42 07 PM" src="https://github.com/user-attachments/assets/f5e3bd09-8dbf-45e3-8a7f-70d7334fd25b" /> <img width="408" height="663" alt="Screenshot 2026-07-29 at 2 44 33 PM" src="https://github.com/user-attachments/assets/6b952a81-40e5-4a9d-b08a-190c71575cac" /> ## Problem Four shared components in `apps/docs` render a hardcoded heading tag no matter where they're used: - `NamedCodeBlock` renders a code block's filename as an `<h6>` - `ProjectConfigVariables` renders a variable label as an `<h6>` - `StepHikeCompact.Details` renders a step title as an `<h3>` - `IconPanel` renders its title as an `<h5>` Since these are fixed, they often land in the wrong spot in a page's heading order (like an h6 right after an h2), which breaks navigation for screen reader users. This showed up in the [header hierarchy triage report](https://app.notion.com/p/supabase/Playwright-E2E-Triage-Reports-3ab5004b775f81e3bc60d058fa5a02c1) — fixing these 4 components alone resolves 72 of the 159 heading-order violations found. ## Solution Swapped the heading tag in each component for a `<span>` with the same classes. None of these are really "headings" for the content that follows, so they shouldn't be in the tag tree at all. The one wrinkle: this codebase applies heading font weight/family through a global CSS rule keyed off the tag name (h1-h6), not something the tag gives you for free. So each span now sets that styling explicitly, plus a margin to match what was there before. Nothing else changed — same classes, same layout. ## Manual testing Staging preview: https://docs-git-ui-header-hierarchy-supabase.vercel.app Check that each one still looks right: - [NamedCodeBlock](https://docs-git-ui-header-hierarchy-supabase.vercel.app/docs/guides/self-hosting/docker) — filenames above the code blocks - [ProjectConfigVariables](https://docs-git-ui-header-hierarchy-supabase.vercel.app/docs/guides/auth/quickstarts/react-native) — the "Project URL" / "Publishable key" labels (this page also has a `NamedCodeBlock` inside the numbered steps) - [StepHikeCompact](https://docs-git-ui-header-hierarchy-supabase.vercel.app/docs/guides/database/beekeeper-studio) — the step titles ("Create a new connection", etc.) - [IconPanel](https://docs-git-ui-header-hierarchy-supabase.vercel.app/docs/guides/resources) — the "Auth0" / "Firebase Auth" panel titles under "Migrate to Supabase" I also ran typecheck, lint, and the docs test suite locally — all green. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated headings and labels across documentation and UI components for more consistent typography. * Improved spacing, font weight, and block-level layout for project variables, step details, code tabs, and icon panels. * Preserved existing text content and conditional display behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
81523d5d8c |
fix(docs): fix heading-order skips in guide and troubleshooting content (#48459)
Closes DOCS-1260 _See WAVE plugin no longer flags a jump in header hierarchy. Preview on left._ <img width="708" height="699" alt="Screenshot 2026-07-29 at 2 30 11 PM" src="https://github.com/user-attachments/assets/be5bf335-9e03-474f-8215-06fa505ab2db" /> ## Problem Beyond the 4 shared components fixed in [#48456](https://github.com/supabase/supabase/pull/48456), the [header hierarchy report](https://app.notion.com/p/supabase/Playwright-E2E-Triage-Reports-3ab5004b775f81e3bc60d058fa5a02c1) found plain content headings that skip a level. For example, you may see a `##` followed directly by an `####`. Jumps in headers breaks page navigation for screen reader users, who jump between headings expecting each level to nest one at a time. ## Solution Adjusted heading levels across the affected guide and troubleshooting pages so every section nests correctly, with no skipped levels. **Staging previews:** | Page | Preview | | --- | --- | | `/guides/api/rest/postgrest-error-codes` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/api/rest/postgrest-error-codes) | | `/guides/auth/oauth-server/getting-started` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/auth/oauth-server/getting-started) | | `/guides/database/custom-postgres-config` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/custom-postgres-config) | | `/guides/database/drizzle` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/drizzle) | | `/guides/database/extensions` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/extensions) | | `/guides/database/extensions/pgaudit` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/extensions/pgaudit) | | `/guides/database/postgres-js` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/postgres-js) | | `/guides/database/replication/manual-replication-monitoring` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/replication/manual-replication-monitoring) | | `/guides/database/replication/manual-replication-setup` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/replication/manual-replication-setup) | | `/guides/database/replication/pipelines-monitoring` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/database/replication/pipelines-monitoring) | | `/guides/functions/debugging-tools` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/debugging-tools) | | `/guides/functions/development-tips` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/development-tips) | | `/guides/functions/examples/auth-send-email-hook-react-email-resend` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/examples/auth-send-email-hook-react-email-resend) | | `/guides/functions/examples/image-manipulation` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/examples/image-manipulation) | | `/guides/functions/examples/semantic-search` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/examples/semantic-search) | | `/guides/functions/examples/send-emails` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/examples/send-emails) | | `/guides/functions/examples/sentry-monitoring` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/examples/sentry-monitoring) | | `/guides/functions/wasm` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/functions/wasm) | | `/guides/getting-started` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/getting-started) | | `/guides/platform/aws-marketplace` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/platform/aws-marketplace) | | `/guides/platform/aws-marketplace/faq` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/platform/aws-marketplace/faq) | | `/guides/platform/billing-faq` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/platform/billing-faq) | | `/guides/platform/ipv4-address` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/platform/ipv4-address) | | `/guides/platform/migrating-within-supabase/backup-restore` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/platform/migrating-within-supabase/backup-restore) | | `/guides/platform/privatelink` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/platform/privatelink) | | `/guides/queues/api` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/queues/api) | | `/guides/resources` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/resources) | | `/guides/security/hipaa-compliance` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/security/hipaa-compliance) | | `/guides/security/security-testing` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/security/security-testing) | | `/guides/security/soc-2-compliance` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/security/soc-2-compliance) | | `/guides/self-hosting` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/self-hosting) | | `/guides/storage/cdn/fundamentals` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/storage/cdn/fundamentals) | | `/guides/storage/debugging/logs` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/storage/debugging/logs) | | `/guides/storage/production/scaling` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/storage/production/scaling) | | `/guides/storage/schema/helper-functions` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/storage/schema/helper-functions) | | `/guides/storage/serving/image-transformations` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/storage/serving/image-transformations) | | `/guides/storage/uploads/resumable-uploads` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/storage/uploads/resumable-uploads) | | `/guides/troubleshooting/an-invalid-response-was-received-from-the-upstream-server-error-when-querying-auth-RI4Vl-` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/an-invalid-response-was-received-from-the-upstream-server-error-when-querying-auth-RI4Vl-) | | `/guides/troubleshooting/are-all-features-available-in-self-hosted-supabase-THPcqw` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/are-all-features-available-in-self-hosted-supabase-THPcqw) | | `/guides/troubleshooting/avoiding-timeouts-in-long-running-queries-6nmbdN` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/avoiding-timeouts-in-long-running-queries-6nmbdN) | | `/guides/troubleshooting/database-api-42501-errors` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/database-api-42501-errors) | | `/guides/troubleshooting/disabling-prepared-statements-qL8lEL` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/disabling-prepared-statements-qL8lEL) | | `/guides/troubleshooting/discovering-and-interpreting-api-errors-in-the-logs-7xREI9` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/discovering-and-interpreting-api-errors-in-the-logs-7xREI9) | | `/guides/troubleshooting/edge-function-504-error-response` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/edge-function-504-error-response) | | `/guides/troubleshooting/high-cpu-and-slow-queries-with-error-must-be-a-superuser-to-terminate-superuser-process` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/high-cpu-and-slow-queries-with-error-must-be-a-superuser-to-terminate-superuser-process) | | `/guides/troubleshooting/how-postgres-chooses-which-index-to-use-_JHrf4` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/how-postgres-chooses-which-index-to-use-_JHrf4) | | `/guides/troubleshooting/how-to-change-max-database-connections-_BQ8P5` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/how-to-change-max-database-connections-_BQ8P5) | | `/guides/troubleshooting/how-to-interpret-and-explore-the-postgres-logs-OuCIOj` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/how-to-interpret-and-explore-the-postgres-logs-OuCIOj) | | `/guides/troubleshooting/how-to-migrate-from-supabase-auth-helpers-to-ssr-package-5NRunM` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/how-to-migrate-from-supabase-auth-helpers-to-ssr-package-5NRunM) | | `/guides/troubleshooting/http-api-issues` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/http-api-issues) | | `/guides/troubleshooting/increase-vector-lookup-speeds-by-applying-an-hsnw-index-ohLHUM` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/increase-vector-lookup-speeds-by-applying-an-hsnw-index-ohLHUM) | | `/guides/troubleshooting/interpreting-supabase-grafana-cpu-charts-9JSlkC` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/interpreting-supabase-grafana-cpu-charts-9JSlkC) | | `/guides/troubleshooting/interpreting-supabase-grafana-io-charts-MUynDR` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/interpreting-supabase-grafana-io-charts-MUynDR) | | `/guides/troubleshooting/new-branch-doesnt-copy-database` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/new-branch-doesnt-copy-database) | | `/guides/troubleshooting/not-receiving-auth-emails-from-the-supabase-project-OFSNzw` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/not-receiving-auth-emails-from-the-supabase-project-OFSNzw) | | `/guides/troubleshooting/resolving-500-status-authentication-errors-7bU5U8` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/resolving-500-status-authentication-errors-7bU5U8) | | `/guides/troubleshooting/resolving-cannot-execute-update-in-a-read-only-transaction-on-transaction-pooler-connections-ef582c` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/resolving-cannot-execute-update-in-a-read-only-transaction-on-transaction-pooler-connections-ef582c) | | `/guides/troubleshooting/resolving-database-hostname-and-managing-your-ip-address-pVlwE0` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/resolving-database-hostname-and-managing-your-ip-address-pVlwE0) | | `/guides/troubleshooting/rls-simplified-BJTcS8` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/rls-simplified-BJTcS8) | | `/guides/troubleshooting/security-of-anonymous-sign-ins-iOrGCL` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/security-of-anonymous-sign-ins-iOrGCL) | | `/guides/troubleshooting/supabase--your-network-ipv4-and-ipv6-compatibility-cHe3BP` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/supabase--your-network-ipv4-and-ipv6-compatibility-cHe3BP) | | `/guides/troubleshooting/supabase-grafana-memory-charts` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/supabase-grafana-memory-charts) | | `/guides/troubleshooting/supavisor-faq-YyP5tI` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/supavisor-faq-YyP5tI) | | `/guides/troubleshooting/tracking-postgres-role-activity-to-specific-dashboard-users-8d3715` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/tracking-postgres-role-activity-to-specific-dashboard-users-8d3715) | | `/guides/troubleshooting/transferring-from-cloud-to-self-host-in-supabase-2oWNvW` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/transferring-from-cloud-to-self-host-in-supabase-2oWNvW) | | `/guides/troubleshooting/understanding-postgresql-explain-output-Un9dqX` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/understanding-postgresql-explain-output-Un9dqX) | | `/guides/troubleshooting/understanding-postgresql-logging-levels-and-how-they-impact-your-project-KXiJRm` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/understanding-postgresql-logging-levels-and-how-they-impact-your-project-KXiJRm) | | `/guides/troubleshooting/vercel-integration-environment-variables-not-syncing-for-persistent-git-branches-b9191e` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/vercel-integration-environment-variables-not-syncing-for-persistent-git-branches-b9191e) | | `/guides/troubleshooting/why-are-there-gaps-in-my-postgres-id-sequence-Frifus` | [Preview](https://docs-git-docs-heading-hierarchy-supabase.vercel.app/docs/guides/troubleshooting/why-are-there-gaps-in-my-postgres-id-sequence-Frifus) | ## Manual testing 1. See affected pages. Recommend running a browser plugin like WAVE and selecting the **Structure** tab. 2. See the headings do not skip. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Documentation** * Standardized heading hierarchy across many guides and troubleshooting articles to improve readability and navigation. * Updated several documentation link targets to the correct new locations. * Reformatted multiple sections (including replication monitoring, Edge Functions, Storage, authentication, security, and networking) without changing instructions. * Queue Data API docs were restructured via heading-level adjustments (no operational changes). * Billing FAQ received clearer, more detailed payment-failure and tax guidance, plus related link updates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
e241a21a9a |
fix: ESLint errors relating to accessibility in table editor, API Key and Access Token (#48479)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Added aria-label attributes and Tooltip to buttons ## What is the current behavior? alt attributes and Tooltip were missing ## What is the new behavior? Buttons have now aria-label attributes and Tooltip. ## Additional context No visual changes have been made. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility Improvements** * Added tooltips and improved accessible labeling for filter removal, sort controls, and action menu triggers. * Enhanced “More actions”/“More options” tooltips and aria-labels for API keys and access tokens. * Updated token scope selection and token banner close actions to use clearer tooltip messaging. * Wrapped panel close control with a tooltip and added an aria-label for clearer screen reader support. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bc95a2f19a |
fix(studio): edge func exec time formatting in reports (#48539)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Fixes Edge Function Execution Time chart within our observability reports time formatting. This also fixes the non-hovered state which would lose the `ms` formatting. | Before | After | |--------|--------| | <img width="2160" height="652" alt="cleanshot_2026-07-29_at_02 15 53_2x" src="https://github.com/user-attachments/assets/cfd6dbc2-f283-4379-a133-581c76990cb5" /> | <img width="797" height="314" alt="Screenshot 2026-07-31 at 14 30 48" src="https://github.com/user-attachments/assets/f5f1ace5-b6ef-43db-aebd-e10d31631013" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved execution-time chart formatting with clearer millisecond values, thousands separators, and configurable precision. * Chart highlights now support custom value formatting alongside existing number, percentage, and byte formats. * **Bug Fixes** * Non-finite execution-time values now display safely as `0ms`. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9b51678fcf |
Revert "feat: update mgmt api docs (#48282)" (#48545)
## What kind of change does this PR introduce?
Revert
## What is the current behavior?
#48282 auto-updated the mgmt API docs spec files
(`apps/docs/spec/api_v1_openapi.json`,
`apps/docs/spec/api_v2_openapi.json`,
`apps/docs/spec/common-api-sections.json`, and the deparsed transform
files).
## What is the new behavior?
Reverts those spec/transform files back to their state prior to #48282.
This reverts commit
|
||
|
|
00d12c305c |
Include Migration steps in changelog bodySection (#48496)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature / refactor ## What is the current behavior? The changelog entry parser extracts `## Migration steps` as a separate field (`migrationSteps`), and the `bodySection` stops before it. This requires consumers to handle migration steps separately from the main body content. ## What is the new behavior? The `bodySection` now includes `## Migration steps` as part of the rendered body content. The `migrationSteps` field has been removed from the `ChangelogEntry` type. The `bodySection` extraction now stops at internal-only planning sections (`## Rollout timeline`, `## Comms timeline`) instead of at migration steps, allowing migration steps to be included in the public-facing body. ## Additional context - Updated `parseChangelogEntryFile` to extract `bodySection` through migration steps, excluding only internal planning tables - Updated the `ChangelogEntry` type documentation to clarify that `bodySection` includes migration steps - Added a test case verifying that migration steps are included in the rendered body while internal sections are excluded - This simplifies the API by consolidating public body content into a single field https://claude.ai/code/session_01X5ikaawVPZwMT5C2dWUyJY <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Changelog entries now include all public content following the Body section, including relevant subsections and rollout information. * Migration guidance is included directly within the main changelog body for a clearer reading experience. * Internal notes, communications, and planning details remain excluded from displayed changelog content. * Unmatched internal markers now correctly hide all subsequent content from public changelogs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
4adef69037 |
feat: update mgmt api docs (#48282)
This PR updates mgmt api docs automatically. Co-authored-by: phamhieu <689843+phamhieu@users.noreply.github.com> |
||
|
|
50e1eb7436 |
chore(eslint): bump eslint-config-next to v16 for useEffectEvent (#48458)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / build (ESLint config upgrade + lint cleanup). ## What is the current behavior? `eslint-plugin-react-hooks` v5 (pulled in transitively by `eslint-config-next` v15) doesn't recognize stable `useEffectEvent`, so every effect that calls an effect-event handler needs an `eslint-disable react-hooks/exhaustive-deps` to silence a false positive. There are 30 such dead disables across Studio. ## What is the new behavior? Bumps `eslint-config-next` to v16, which pulls in `eslint-plugin-react-hooks` v7 whose `exhaustive-deps` understands `useEffectEvent`, and removes the 30 now-dead disable directives (and their orphaned explanatory comments). Supporting changes: - **Flat-config migration**: v16 is a native flat-config array (v15 was eslintrc), so `eslint-config-supabase` now spreads it directly instead of bridging through `FlatCompat`. - **React Compiler rules off**: v16 enables react-hooks v7's `recommended`, which layers the React Compiler lint rules on top of the two classic rules. These are switched off (derived dynamically from what next enables) to keep this change scoped to the `exhaustive-deps` improvement. - **Plugin-registration fallout** (v16 scopes plugin registration to a file glob rather than registering globally like FlatCompat did): stop re-registering `@typescript-eslint` (shared) and `jsx-a11y` (studio); scope our react / react-hooks / jsx-a11y rule overrides (studio, www) to v16's plugin glob so they don't error on files outside it (e.g. `.cjs`). - **Lint surface preserved**: v16's glob newly includes `.mts`/`.cts` (v15 didn't lint them), which surfaced pre-existing errors in tooling scripts. The shared config keeps the prior surface by leaving `.mts`/`.cts` unlinted; linting them is left as a separate change. - **Ratchet**: rebaselines `@tanstack/query/exhaustive-deps` 9 → 89. v15 forced next's `@babel/eslint-parser` onto `.ts` files, hiding these deps; v16 parses `.ts` with `@typescript-eslint/parser` and correctly surfaces the intentional `connectionString`-excluded-from-`queryKey` pattern. Worth a follow-up to review whether any are real cache-correctness bugs. - Drops three now-dead devDeps from `eslint-config-supabase`: `@eslint/eslintrc`, `@eslint/js`, `@typescript-eslint/eslint-plugin`. Verified locally: `turbo run lint` → 7/7 packages pass with 0 errors; Studio `lint:ratchet` passes; Prettier clean on changed files; typecheck unaffected. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Refined linting configuration and removed outdated lint suppressions across Studio. * Updated Next.js linting support and refreshed related development configuration. * Expanded lint baseline coverage for query-related code. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
009528c6ca |
chore: update Lovable homepage logo (#48536)
## Summary - replace the outdated Lovable homepage logo |
||
|
|
27f18f0359 |
Spring Boot Quickstart (#48396)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update ## What is the new behavior? Spring Boot quickstart guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a “Use Supabase with Spring Boot” quickstart guide, including project setup, Session pooler/JPA configuration, sample entity/repository, seed data, and a `GET /instruments` endpoint. - Added “Spring Boot” to the Getting Started “Framework Quickstarts” navigation, shown only when not in JS-only mode. - Added a Spring Boot AI prompt with step-by-step integration instructions. - **Documentation** - Updated MDX linting rules to allow “Spring Boot” and “Spring Data JPA” headings, and to permit “Initializr” spelling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
c613a9b92e |
chore: update realtime error codes & add troubleshotting page (#48381)
* Update realtime error codes * Add new troubleshooting page for client presence rate error * Fix references from error codes to work with relative paths |
||
|
|
fd67a8014f |
Joshen/fe 4018 bug gh branch validation in branch modal fails silently if (#48432)
## Context Realised that if the project has a GH integration, but the user's account is not connected to GH - the branch validation in the "Sync with Git Branch" field will not work. The Edit branch modal also obfuscates the error being returned from the validation API so its not clear what the issue is <img width="500" alt="image" src="https://github.com/user-attachments/assets/739dfe7c-8920-4edf-a751-63d7f6273db4" /> Opting to show an "Authorize" CTA for this scenario so it's clear from the user's POV what to do (Refer to "To test" below for screenshots) ## To test - [ ] Verify that on an account which isn't connect to GH + project with no GH integration - CTA is as per normal ("Configure") which should direct you to the settings -> integrations page (Same for edit branch) <img width="500" alt="image" src="https://github.com/user-attachments/assets/9a010fde-8ab0-43d6-b5c9-ced9fed1426e" /> <img width="500" alt="image" src="https://github.com/user-attachments/assets/d129cccf-7238-4305-913b-0cf78c7dcc26" /> - [ ] Set up a GH integration and check Create / Edit branch - the branch input field should work with proper branch name validation <img width="500" alt="image" src="https://github.com/user-attachments/assets/4d643956-2d11-406b-b198-193f3221b7a9" /> - [ ] Now go to Account settings and remove the GH connection, then check the Create / Edit branch modals - should have the "Authorize" CTA (instead of the input field) <img width="500" alt="image" src="https://github.com/user-attachments/assets/ac152c0d-2e9c-4d89-95bc-36127c0fc8df" /> <img width="500" alt="image" src="https://github.com/user-attachments/assets/d1f50d38-d801-4546-96fd-8cf3b5d0f805" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a “Sync with a GitHub branch” connection entry with an inline authorize flow. * Integrated GitHub authorization awareness into branch create/edit modals so users are guided to authorize or proceed to syncing. * **Bug Fixes** * Unified loading, success, and error handling for GitHub authorization/connection checks across create and edit flows. * Improved Git branch validation messaging to show cleaner error text. * **Accessibility/UX** * Updated modal UI text and added an explicit label for the “Include data” toggle. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
97a935fb4f |
docs(csharp): update C# reference docs to SDK 1.5 (#48523)
## What Brings the C# client reference in line with `supabase-csharp` 1.5. The reference spec had drifted ~2 years and was missing most of the Auth, MFA, Admin, and Storage surface. ## Changes - **Fix example errors** in the v1 reference spec — corrected the `From<T>()`/`Table<T>()` model example, `ListenType` realtime enum, a mislabeled code fence, and other small mismatches. - **Backfill release notes** from 1.0.1 through 1.5.0, reconstructed by diffing the `Supabase.csproj` dependency pins across git tags and pulling highlights from each sub-package changelog. - **Document the undocumented API surface** (~27 new entries): Auth (anonymous, ID token, SSO, refresh, link/unlink identity, code exchange, reauthenticate, scoped sign-out), the full MFA API, the Admin API via `AdminAuth`, and Storage (`Copy`, signed URLs, signed uploads). - **Fix a latent bug**: the `ResetPasswordForEmail()` entry used a spec id that matched no canonical section, so it never rendered. Renamed to `reset-password-for-email`. ## Notes - All signatures verified against the 1.5 SDK source. - Entries render only when their spec id matches a slot in the shared `common-client-libs-sections.json`; ids were mapped against that set. - Spec YAML is Prettier-clean under the repo config. Closes SDK-1369. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added C# release notes covering versions 1.0.1–1.5.0. * Updated C# client documentation with current initialization patterns and expanded authentication, session, identity, PKCE, MFA, Realtime, Storage, and admin operation examples. * Added Storage examples for file copying, signed URLs, signed uploads, and uploads through signed URLs. * Corrected code samples and clarified scoped sign-out and password-reset guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a76f1f0c9b | feat: Move search functionality to Vercel function (#48443) | ||
|
|
6a99952af5 | docs(self-hosted): update nav and minor corrections (#48499) | ||
|
|
ca94d842a7 |
design demo: security page content additions (content-only) (#48403)
## Summary - Adds four missing content cards to the existing `security.mdx` using the same `Section` component and grid already on the page — no new UI components or features - Cards added: **GDPR & European Compliance**, **Data Residency**, **Data Processing Agreement**, **Shared Responsibility** - Also fixes the HIPAA shared responsibility link path (`/deployment/` not `/platform/`) Worth validating still. ## What this is A content-only drop-in that addresses some gaps ## What's out of scope here - No sticky nav, tables, plan comparison grids, or new components - No DPA request automation — just a plain link to `/legal/dpa` - No plan-gating claims (removed — accuracy unconfirmed) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized the security page into clearer, grouped sections (Compliance, Data, Configuration, and Misc) for easier navigation. * Expanded compliance coverage with HIPAA, ISO 27001, GDPR & European compliance, and updated shared responsibility details. * Added new content for data residency and a Data Processing Agreement section. * Reordered configuration items (multi-factor authentication, role-based access, vulnerability management, DDoS) and moved payment processing into the Misc section. * Updated icons and card layout visuals throughout the page. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Nik Richers <nrichers@gmail.com> |
||
|
|
c4c58ef3e3 |
feat: remove pandadoc dpa request flow (#48525)
Terms of Service v3 (effective August 1, 2026, #48482) incorporates the Data Processing Addendum by reference, so customers no longer sign a separate DPA. Legal confirmed the PandaDoc signing flow can go; previously signed DPAs remain binding. This removes the frontend flow only. I'll remove the platform endpoint (`POST /platform/organizations/{slug}/documents/dpa`) separately once the PandaDoc contract conversation wraps. **Changed:** - **Dashboard DPA card no longer requests PandaDoc documents**: the Request DPA button and confirm modal are replaced with a View DPA link to the canonical legal page, with evergreen copy explaining the DPA is part of the Terms. Tracked via the same `document_view_button_clicked` event the other document cards use. - **Legacy `/legal/dpa` page retired**: the page told users to request a signed DPA from the dashboard, which no longer exists. It now permanently redirects to `/legal/customer-resources/data-processing-addendum` (the follow-up already flagged in #48483), and the footer link is removed. The `dpa_pdf_opened` and `dpa_request_button_clicked` events are removed with their last call sites. The latest privacy version links the canonical page directly; archived v1/v2 keep their original `/legal/dpa` link, served by the redirect. - **Orphaned DPA PDFs removed**: the four dated `Supabase+DPA+*.pdf` files under `/downloads/docs` had zero remaining references once the signing flow is gone. No redirect: nothing links these URLs, so they 404. - **Subscription tracking**: the subprocessor updates form now fires `www_subprocessor_updates_subscribed` on successful submit, so we can measure uptake of the notification list that replaces per-customer DPA emails. ## To test Verified on the Vercel previews (Playwright): - [x] Studio: `/org/_/documents` shows the DPA card with the incorporation copy and a working View DPA link (href = canonical page); no Request DPA button, no PandaDoc mention; TIA/SOC2/ISO27001/HIPAA cards unaffected - [x] www: `/legal/dpa` permanently redirects to `/legal/customer-resources/data-processing-addendum`; footer no longer shows DPA; zero console errors - [x] www: subscribing on the subprocessor page succeeds (200 from the form route, profile created with topic_4) and fires `www_subprocessor_updates_subscribed` (201 from the telemetry endpoint); test profile unsubscribed afterwards - [x] www: `/downloads/docs/Supabase+DPA+260601.pdf` returns 404 with no redirect; DPA card copy verified without the effective date ## Linear - fixes GROWTH-1068 |
||
|
|
4ae0c08967 |
feat: tos v3 update banner + publish subprocessor list (#48524)
Terms of Service v3 (effective August 1, 2026, #48482) incorporates the Data Processing Addendum by reference, and Legal asked for an in-app notice announcing the change. The subprocessor list page that the new Terms, DPA, and notice all point at was merged as an intentionally hidden draft (#48100) and never un-hidden. **Changed:** - **Dashboard ToS-update banner**: re-enables `BannerTOSUpdate` with the v3 copy provided by Legal (DPA incorporation, subprocessor list location, fees provisions). New expiry (August 29) and a new localStorage key, since anyone who dismissed the May v2 banner would otherwise never see this one. - **Subprocessor list page published**: removes `noindex,nofollow` and links the page from the Legal Hub index, so the page customers are told to subscribe on is actually discoverable. - **Studio e2e fixture updated**: the global Playwright fixture suppressed the banner via the old localStorage key; with the gate live again it would have rendered the banner into every e2e run. It now sets the new key. ## To test Verified on the Vercel previews : - [x] Studio: banner renders on dashboard load with the Notice badge and new copy; Learn more dialog shows the three changes with correct hrefs (DPA page, subprocessor list, /terms); Understood dismisses and persists across reload via `terms-of-service-update-2026-08-01` - [x] www: `/legal` lists Subprocessor List under Customer Legal Resources; `/legal/customer-resources/subprocessor-list` serves `robots` meta `index,follow` and renders the download button + subscribe form; zero console errors on all tested pages ## Linear - fixes GROWTH-1067 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a publicly accessible Subprocessor List to the legal resources. * Updated the Terms of Service notice to reflect the August 1, 2026 update, including data processing, subprocessors, fraud prevention, and consumer provisions. * **Documentation** * Made the Subprocessor List discoverable through standard search indexing and the legal resources page. * Extended the Terms of Service banner availability through August 29, 2026. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e6b8725571 |
feat(account): require a user to name their TOTP authenticator (#48493)
Currently it's an autogenerated name. We want users to explicitly enter a name for their authenticator so that: - They can remember that they took the action of registering an authenticator - They can see a meaningful name during sign-in if they have multiple TOTP authenticators <img width="536" height="269" alt="Screenshot 2026-07-30 at 16 05 10" src="https://github.com/user-attachments/assets/e43de27f-b4ca-4d4f-969a-578267eeebe4" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Bug Fixes** * Improved TOTP enrollment: confirmation is no longer enabled unless an authenticator app name is provided (validated beyond whitespace). * **UI Improvements** * Updated the authenticator app name label/description, added an example placeholder, and auto-focused the field when the confirmation step appears. * Refined the on-screen guidance for suggested authenticator apps (e.g., Google Authenticator or 1Password). <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0e92a9574c |
Joshen/fe 3932 support branching conversations (#48519)
## Context Adds support for branching off from an Assistant's Response - which creates a new chat with all the previous messages including from where we're branching off from <img width="204" height="97" alt="image" src="https://github.com/user-attachments/assets/0b171ae6-f2b4-4b58-87fa-0010ad45f777" /> Branched conversations will have an indication of where it was branched off from <img width="404" height="427" alt="image" src="https://github.com/user-attachments/assets/bed8502f-3f83-4f76-bc00-feac86fa57a6" /> ## Other changes - Also added support for copying an Assistant's Response <img width="190" height="115" alt="image" src="https://github.com/user-attachments/assets/5e4aa0b8-eb6e-485f-80c0-3028b95720f7" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Branch conversations from assistant messages into a new chat. * View the originating conversation and navigate back to it. * Copy assistant message content with visual confirmation. * Access branching and copying actions from message controls. * **UI Updates** * Added “Branched from” indicators for branched conversations. * Updated the assistant disclaimer text to “The Assistant.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fc5e03f9e3 |
[FE-4019] fix(studio): direct-only connection strings with SSL params for Multigres (#48433)
Multigres (high-availability) projects only accept TLS connections with direct SSL negotiation, and they don't support connection pooling at all — neither Supavisor nor the dedicated PgBouncer pooler exists for them. Studio previously showed pooler connection strings that would fail with "server closed the connection unexpectedly". This PR makes every connection-string surface direct-only for HA projects and appends `?sslmode=require&sslnegotiation=direct` to the examples. Non-HA projects are unchanged. Addresses [FE-4019](https://linear.app/supabase/issue/FE-4019/append-ssl-params-to-multigres-connection-string-examples-in-ui) **Changed:** - `buildConnectionStringPooler` gets an HA branch that collapses every slot in the bag to the direct connection string with the SSL params appended (mirroring the existing CLI branch, which also has no pooler) — dedicated slots come back `undefined` and `ipv4SupportedForDedicatedPooler` is forced off. Since HA never reaches the pooler layout anymore, the earlier per-URI SSL-append logic on pooler strings is removed - `useConnectState` coerces `connectionMethod` to `direct` and `useSharedPooler` to `false` for HA projects. The Connect sheet restores the last-used method from localStorage shared across projects, so a "Transaction pooler" selection made on a regular project could otherwise leak pooler-flavored notices, badges, and telemetry into an HA project - Prisma and Drizzle ORM tabs get an HA branch: `DATABASE_URL`/`DIRECT_URL` both use the direct connection, no `?pgbouncer=true` appended, with a comment explaining Multigres doesn't support pooling. The 5-arm nested ternaries in both files are flattened into `getEnvCode` helpers that switch on a shared `resolveOrmConnectionScenario` helper (`OrmConnection.utils.ts`), so the deployment-mode/HA branching lives in one tested place and each file keeps only its own formatting - The PgBouncer and Supavisor config queries are disabled (`enabled: !isHighAvailability`) in the Connect sheet — those endpoints serve pooler config that doesn't exist on Multigres - `parseConnectionParams` keeps the URI's query string in a new `search` field so formats rebuilt from parsed parts can carry it - psql switches from the `-h/-p/-d/-U` flag form to the quoted-URI form when query params are present (flags can't express them; psql still prompts for the password) - JDBC appends the params using pgJDBC's casing (`sslNegotiation`, supported since 42.7.4) - Prisma's `?pgbouncer=true` appends are query-aware (join with `&` when the URI already has a query string) via a new `appendConnectionStringParams` helper - The project home "Direct connection string" copy item also appends the params for HA projects **Added:** - Unit tests for the HA collapse behavior (all slots direct, dedicated config and IPv4 add-on ignored, no SSL params on non-HA output), the `useConnectState` coercion, the psql/JDBC builders (moved from `content.tsx` into `ConnectionString.utils.ts` so they're testable), and `resolveOrmConnectionScenario` (every deployment-mode/HA/pooler branch) **Known gaps (left out deliberately):** - The grid ExportDialog psql/pg_dump commands, the .NET `appsettings.json` (Npgsql only supports direct negotiation from v9 via `SSL Negotiation=Direct`), and the SQLAlchemy keyword-style `.env` are flag/keyword forms that can't carry the URI params — these would still fail against Multigres and need a follow-up - Settings > Database's Connection Pooling section and the pooler logs page have no HA gating yet — they'd still render pooler config UI for a Multigres project and should be hidden in a follow-up ## To test On a **Multigres (HA) project** (staging only supports `us-east-1` for Multigres): - Open the Connect sheet → Direct tab: there's no connection-method picker, and the connection string is the direct one ending with `?sslmode=require&sslnegotiation=direct` for the URI, PHP, and psql (quoted-URI form) types; JDBC includes `&sslmode=require&sslNegotiation=direct` - ORM tab → Prisma: both `DATABASE_URL` and `DIRECT_URL` are the direct connection string with the SSL params, no `pgbouncer=true`, with a "Multigres does not support connection pooling" comment. Drizzle likewise shows the direct string only - Framework tabs (e.g. Next.js): every `DATABASE_URL` carries the direct string with the params exactly once - Open the network tab: no requests to `/config/pgbouncer` or `/config/supavisor` while using the Connect sheet - To check the localStorage coercion: on a **regular** project pick "Transaction pooler" in the Connect sheet, then open the sheet on the Multigres project — no pooler badge/notices, string is still direct - Copy the URI, substitute your password, and `psql "<string>"` — it should connect - Project home → Copy dropdown → "Direct connection string" includes the params On a **regular (non-Multigres) project** — confirm nothing changed: - Connect sheet: direct/session/transaction strings for all connection types (URI, psql flag form, JDBC, PHP) look the same as before, no SSL params appended - Prisma/Drizzle tabs render identically (`?pgbouncer=true` still appended with `?`, dedicated-pooler alternatives still shown per IPv4 add-on state) - Project home copy dropdown is unchanged <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Enhanced connection-string generation for high-availability projects, including required SSL settings for direct connections. * Preserved URI query parameters in PostgreSQL, `psql`, JDBC, and generated environment configurations. * Improved ORM environment templates with clearer handling for pooler and high-availability connection scenarios. * **Bug Fixes** * High-availability projects now consistently use direct connections instead of pooler options. * Connection strings and generated templates update correctly when availability settings change. * **Tests** * Expanded coverage for query parameters, high-availability behavior, and connection scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
78957bcd68 |
Replace disable pipelines cta with enable pipelines if pipelines not enabled yet (#48518)
## Context Addresses 2 issues found for the Replication UI - "Disable Pipelines" CTA was still being shown despite Pipelines not being enabled yet - Opting to show the "Enable Pipelines" CTA instead in this case, which will open the `EnablePipelinesModal` <img width="269" height="162" alt="image" src="https://github.com/user-attachments/assets/41e5ec7d-11b1-4008-ae9d-64def00329eb" /> - Fixes "Disable Pipelines" being incorrectly disabled <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added options to enable or disable Pipelines directly from the replication destinations menu. * Added an enablement modal with messaging and upgrade actions based on available access. * Added support for opening the Pipelines modal through external controls. * **Bug Fixes** * Corrected action disabled states and destination-removal guidance. * Improved error handling when disabling Pipelines, including a reliable fallback message. * Refined modal and dialog layout spacing for a more consistent presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4381e1290c |
fix(studio): replace form-group green focus shadows with focus-ring (#48221)
## What kind of change does this PR introduce? Bug fix / a11y cleanup ([DEPR-629](https://linear.app/supabase/issue/DEPR-629)). ## What is the current behavior? `apps/studio/styles/globals.css` still styles `.form-group` / `.form-control` inputs with a legacy soft green focus glow (`box-shadow: … rgba(62, 207, 142, …)` plus `ring-current`). That can fight modern focus rings if those classes are ever present. ## What is the new behavior? Those legacy focus rules are removed. Matching inputs use `@apply focus-ring` instead. | Before | After | | --- | --- | | <img width="882" height="246" alt="CleanShot 2026-07-31 at 13 28 42@2x" src="https://github.com/user-attachments/assets/3aa00e2f-918f-4e72-9db0-4ad75864cc58" /> | <img width="864" height="244" alt="CleanShot 2026-07-31 at 13 28 57@2x" src="https://github.com/user-attachments/assets/4a96439d-16de-4ebb-ab07-2ae7cbf46c0b" /> | ## To test These CSS selectors are legacy. Easiest before/after is a one-line probe in the browser. 1. Open the **Studio preview** for this PR (and, for comparison, production Studio or `master`). 2. Go to any project (any page is fine). 3. Open DevTools → Console and paste: ```js document.body.insertAdjacentHTML( 'beforeend', `<div class="form-group" style="position:fixed;right:16px;bottom:16px;z-index:9999;padding:12px;background:var(--background);border:1px solid var(--border);border-radius:8px"> <label style="display:block;margin-bottom:8px">Legacy form-group probe</label> <input type="text" value="Tab to me" /> </div>` ) ``` 4. Click the injected input (or Tab to it). | | Focus look | | --- | --- | | **Before** (production / `master`) | Soft **green** halo | | **After** (this PR) | Shared **`focus-ring`** only (no green glow, no double stack) | Optional smoke (no visual change expected): **Project Settings → General → Project name** — Tab into the field; normal shared focus ring still works. ## Additional context - Related: #41575, DEPR-628 |
||
|
|
d1e7c403ac |
fix(ui): align Admonition titles and docs link hover with prose (#48428)
## What kind of change does this PR introduce? UI bug fix. ## What is the current behavior? After the recent Admonition a11y refactor: - Titled Admonitions in MDX (blog and docs) could pick up large prose top margin on the title, or (after follow-ups) end up with a title much smaller than the body because the title was a `div` at `text-sm` while body `<p>`s took prose ~15px - Docs MDX links (including inside Admonitions) had a weak hover: prose only shifted underline colour Prior issues: - A couple of guide callouts bolded link text via `[**…**](…)` - Some funky Admonition formatting as called out in comments below ## What is the new behavior? - `AlertTitle` is a `<p>` with `!mt-0 mb-0.5 font-medium` (not an `h5` / bare `div`), so it does not break heading hierarchy and matches admonition body font-size under prose - Admonition uses `AlertTitle` again (though with `<p>` as explained above) and wraps MDX `children` in `AlertDescription` (same as `description`) - `Alert` / `AlertTitle` / `AlertDescription` get `data-slot` attributes; description keeps string→`<p>` wrapping, Studio density, plus `text-balance` - Docs link hover: typography `a:hover` and `MdxAnchor` now move text + decoration toward foreground (InlineLink-like), without stealing brand link colour via `text-inherit` - Content: remove accidental bold on oauth-scopes and multi-factor-authentication guide links | Before | After | | --- | --- | | <img width="1360" height="378" alt="CleanShot 2026-07-29 at 16 44 48@2x" src="https://github.com/user-attachments/assets/1aa98cb4-e691-428e-b7e2-a78afcdf518d" /> | <img width="1350" height="362" alt="CleanShot 2026-07-29 at 16 44 08@2x" src="https://github.com/user-attachments/assets/63c9c7df-c1c7-49c4-8fdb-0411ae251a71" /> | | <img width="1518" height="448" alt="CleanShot 2026-07-29 at 16 46 18@2x" src="https://github.com/user-attachments/assets/d618e138-fcd7-4a44-b16d-cb0ac5ba6b0e" /> | <img width="1524" height="424" alt="CleanShot 2026-07-29 at 16 46 30@2x" src="https://github.com/user-attachments/assets/dbc7710e-42c6-483c-b367-19b2ff3a6475" /> | | <img width="1524" height="598" alt="CleanShot 2026-07-29 at 16 47 15@2x" src="https://github.com/user-attachments/assets/c9c07f37-4e2b-40fa-bc90-c86a17e5ea32" /> | <img width="1530" height="584" alt="CleanShot 2026-07-29 at 16 47 39@2x" src="https://github.com/user-attachments/assets/806735f0-fa44-42e6-bd5a-127899d0bfc2" /> | ## To test **Docs** 1. [Functions quickstart](https://docs-git-fix-admonition-alert-title-prose-supabase.vercel.app/docs/guides/functions/quickstart): titled tip near the top. Title and body should be the same size, no giant gap above the title 2. [BYO MCP](https://docs-git-fix-admonition-alert-title-prose-supabase.vercel.app/docs/guides/ai-tools/byo-mcp): tip with links. Hover a link (text + underline should both go foreground) 3. [OAuth scopes](https://docs-git-fix-admonition-alert-title-prose-supabase.vercel.app/docs/guides/integrations/build-a-supabase-oauth-integration/oauth-scopes): note link is not bold 4. [Multi-factor authentication](https://docs-git-fix-admonition-alert-title-prose-supabase.vercel.app/docs/guides/platform/multi-factor-authentication): same, note link not bold **Blog** 5. [CLI v2 config as code](https://zone-www-dot-com-git-fix-admonition-alert-title-prose-supabase.vercel.app/blog/cli-v2-config-as-code): titled Admonitions. Title size matches body, no huge top margin **Other** 6. [Design system: Admonition](https://design-system-git-fix-admonition-alert-title-prose-supabase.vercel.app/design-system/docs/fragments/admonition): component reference 7. Studio (e.g. project Edge Functions secrets): Admonitions should stay compact `text-sm` outside prose. Preview: [studio-staging](https://studio-staging-git-fix-admonition-alert-title-prose-supabase.vercel.app) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * None * **Style** * Improved link decoration consistency (underline/hover) across internal and external documentation content, with safer external link handling. * **Bug Fixes** * Refined alert/admonition rendering for clearer title/description semantics and better spacing/text wrapping. * Updated documentation image rendering to avoid forwarding whitespace-only children and adjusted chart image layout. * **Tests** * Expanded assertions for alert/admonition structure and styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |